瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 中了backdoor.gpigeon.2006.iw,该怎么办啊,谁帮我看看【求助】

12   1  /  2  页   跳转

中了backdoor.gpigeon.2006.iw,该怎么办啊,谁帮我看看【求助】

中了backdoor.gpigeon.2006.iw,该怎么办啊,谁帮我看看【求助】

今天用瑞星查杀病毒,发现好多backdoor.gpigeon.2006.iw病毒,显示清楚成功了,可下次查还有,杀不清啊,该怎么办啊,急死我了,大家帮帮我啊,谢谢
最后编辑2006-06-12 12:11:33
分享到:
gototop
 

Logfile of HijackThis v1.99.1
Scan saved at 9:57:28, on 2006-6-12
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
F:\KV2006\KVSrvXP.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\Rundll32.exe
C:\WINNT\system32\ctfmon.exe
C:\WINNT\System32\hkcmd.exe
F:\KV2006\KVMonXP.kxp
C:\Program Files\Rising\Rav\RavTask.exe
F:\下载\magicset739\MagicSet\DS.EXE
C:\Program Files\KVFW\kvfw.exe
C:\Program Files\Rising\Rav\Ravmon.exe
F:\KV2006\TrojDie.kxp
F:\KV2006\KRegEx.exe
F:\KV2006\UIHost.exe
C:\Program Files\ChinaNet\VnetClient.exe
C:\Program Files\Rising\Rav\Rav.exe
C:\Program Files\Rising\Rav\RsAgent.exe
C:\WINNT\msagent\AgentSvr.exe
F:\工具\MYIE2\MYIE.EXE
F:\工具\xunlei\Thunder.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.248\HijackThis.exe

R3 - URLSearchHook: BDSrchHook Class - {2C5AA40E-8814-4EB6-876E-7EFB8B3F9662} - C:\WINNT\DOWNLO~1\BDSrHook.dll
O1 - Hosts: www.cnmir.net
O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINNT\System32\xunleibho_v11.dll
O2 - BHO: FiltrateWebObj Class - {42AFACEE-2A77-41EB-9EE2-D9F8AF827F90} - F:\KV2006\KVBHO.dll
O2 - BHO: VnetCookie Class - {4E83D567-4697-4F7B-B1F0-A513B01DB89A} - c:\PROGRA~1\chinanet\VNETTR~1.DLL
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - F:\工具\QQIEHelper.dll
O2 - BHO: BrowseHelper Class - {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} - F:\KV2006\KvShell.dll
O2 - BHO: BDHlprObj Class - {CA92B524-BC8A-4610-BD2C-6BD3E28155D0} - C:\WINNT\DOWNLO~1\BDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@2052,电台(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: 江民杀毒工具栏 - {B5A34A93-D538-43A7-8371-864CB6148D12} - F:\KV2006\KvShell.dll
O3 - Toolbar: 上网助手 - {BB936323-19FA-4521-BA29-ECA6A121BC78} - C:\PROGRA~1\3721\assist\asbar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] ; C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] ; SOUNDMAN.EXE
O4 - HKLM\..\Run: [KvMonXP] "F:\KV2006\KVMonXP.kxp" /auto
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\Run: [PCSuiteTrayApplication] ; C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] ; C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [stup.exe] C:\PROGRA~1\TENCENT\Adplus\stup.exe
O4 - HKLM\..\Run: [Super Rabbit Desktop Set] F:\下载\magicset739\MagicSet\DS.EXE /Load
O4 - HKCU\..\Run: [KVFW] C:\Program Files\KVFW\kvfw.exe -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [KvXP] "F:\KV2006\KvXP.kxp" /ScanBoot /ScanSys
O4 - HKCU\..\Run: [PcSync] ; C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - Startup: 腾讯QQ.lnk = ?
O8 - Extra context menu item: &使用迅雷下载 - F:\工具\xunlei\geturl.htm
O8 - Extra context menu item: &使用迅雷下载全部链接 - F:\工具\xunlei\getallurl.htm
O8 - Extra context menu item: 上传到QQ网络硬盘 - F:\工具\AddToNetDisk.htm
O8 - Extra context menu item: 导出到 Microsoft Office Excel(&X) - res://F:\工具\OFFICE~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\工具\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\工具\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\工具\SendMMS.htm
O9 - Extra button: 信息检索 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\工具\OFFICE~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - F:\工具\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - F:\工具\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - F:\工具\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - F:\工具\QQIEHelper.dll
O11 - Options group: [TBH]  搜搜地址栏搜索
O15 - Trusted Zone: http://www.icbc.com.cn
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1147066410726
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1147066919808
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A34D348-3EAF-4BEA-B6B5-AACC4F1CFE72}: NameServer = 202.102.192.68 202.102.199.68
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: KVSrvXP - Jiangmin Co. Ltd - F:\KV2006\KVSrvXP.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe

帮我看看啊,上面是日志,谢谢
gototop
 

下面是进程结果,帮我看看,谢谢

附件附件:

下载次数:230
文件类型:image/pjpeg
文件大小:
上传时间:2006-6-12 10:39:56
描述:



gototop
 

刚才没弄好,下面这个是,帮我看看啊,谢谢

附件附件:

下载次数:271
文件类型:image/pjpeg
文件大小:
上传时间:2006-6-12 10:43:00
描述:



gototop
 

不好意思啊,搞错了,下面这个是吗?帮我看看,谢谢

附件附件:

下载次数:254
文件类型:image/pjpeg
文件大小:
上传时间:2006-6-12 10:58:11
描述:



gototop
 

你看我的瑞星扫描结果

附件附件:

下载次数:231
文件类型:image/pjpeg
文件大小:
上传时间:2006-6-12 11:04:52
描述:



gototop
 

2006-06-12,11:26:17

System Repair Engineer 2.0.21.505 (2.0 RC 2)
Smallfrogs (http://www.KZTechs.com)

Windows 2000 Professional Service Pack 4 (Build 2195)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <KVFW><C:\Program Files\KVFW\kvfw.exe -silent>  [Beijing Jiangmin.]
    <ctfmon.exe><C:\WINNT\system32\ctfmon.exe>  [Microsoft Corporation]
    <KvXP><"F:\KV2006\KvXP.kxp" /ScanBoot /ScanSys>  [Jiangmin Co.Ltd]
    <PcSync><; C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog>  [Time Information Services Ltd.]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <Synchronization Manager><mobsync.exe /logon>  [Microsoft Corporation]
    <IgfxTray><; C:\WINNT\System32\igfxtray.exe>  [Intel Corporation]
    <HotKeysCmds><C:\WINNT\System32\hkcmd.exe>  [Intel Corporation]
    <SoundMan><; SOUNDMAN.EXE>  [Avance Logic, Inc.]
    <KvMonXP><"F:\KV2006\KVMonXP.kxp" /auto>  [Jiangmin Co.Ltd]
    <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [Microsoft Corporation]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <PCSuiteTrayApplication><; C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray>  [Nokia]
    <DataLayer><; C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE>  [Nokia Mobile Phones Ltd.]
    <stup.exe><C:\PROGRA~1\TENCENT\Adplus\stup.exe>  [Tencent]
    <Super Rabbit Desktop Set><F:\下载\magicset739\MagicSet\DS.EXE /Load>  [Super Rabbit Software]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [Microsoft Corporation]
    <Userinit><C:\WINNT\system32\userinit.exe,>  [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{BC207F7D-3E63-4ACA-99B5-FB5F8428200C}><C:\WINNT\DOWNLO~1\BDPlugin.dll>  []
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINNT\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
[HKEY_CURRENT_USER\Control Panel\Desktop]
    <SCRNSAVE.EXE><(无)>  []

==================================
启动文件夹
[腾讯QQ]
  <C:\Documents and Settings\Administrator\「开始」菜单\程序\启动\腾讯QQ.lnk><H>

==================================
服务
[Bluer Web Server / Bluer Web Server]
  <C:\Program Files\Common Files\minfo.exe><N/A>
[Logical Disk Manager Administrative Service / dmadmin]
  <C:\WINNT\System32\dmadmin.exe /com><VERITAS Software Corp.>
[KVSrvXP / KVSrvXP]
  <F:\KV2006\KVSrvXP.exe /Service><Jiangmin Co. Ltd>
[Rising Process Communication Center / RsCCenter]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>

==================================
浏览器加载项
[ThunderIEHelper Class]
  {0005A87D-D626-4B3A-84F9-1D9571695F55} <C:\WINNT\System32\xunleibho_v11.dll, Thunder Networking Technologies,LTD>
[FiltrateWebObj Class]
  {42AFACEE-2A77-41EB-9EE2-D9F8AF827F90} <F:\KV2006\KVBHO.dll, Jiangmin Co.Ltd>
[VnetCookie Class]
  {4E83D567-4697-4F7B-B1F0-A513B01DB89A} <c:\PROGRA~1\chinanet\VNETTR~1.DLL, >
[QQBrowserHelperObject Class]
  {54EBD53A-9BC1-480B-966A-843A333CA162} <F:\工具\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[BrowseHelper Class]
  {80BF4637-D65B-43F3-BB60-C5DD3D5FB7B9} <F:\KV2006\KvShell.dll, Jiangmin Co.Ltd>
[BDHlprObj Class]
  {CA92B524-BC8A-4610-BD2C-6BD3E28155D0} <C:\WINNT\DOWNLO~1\BDHelper.dll, >
[信息检索(&R)]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <F:\工具\OFFICE~1\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[@shdoclc.dll,-866]
  {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[QQ]
  {c95fe080-8f5d-11d2-a20b-00aa003c157b} <F:\工具\QQ.EXE, TENCENT>
[QQIEFloatBarCfgCmd Class]
  {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <F:\工具\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
[@msdxmLC.dll,-1@2052,电台(&R)]
  {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINNT\System32\msdxm.ocx, Microsoft Corporation>
[江民杀毒工具栏]
  {B5A34A93-D538-43A7-8371-864CB6148D12} <F:\KV2006\KvShell.dll, Jiangmin Co.Ltd>
[上网助手]
  {BB936323-19FA-4521-BA29-ECA6A121BC78} <C:\PROGRA~1\3721\assist\asbar.dll, 3721>
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINNT\System32\wuweb.dll, Microsoft Corporation>
[MUWebControl Class]
  {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINNT\System32\muweb.dll, Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINNT\system32\Macromed\Flash\Flash8b.ocx, Macromedia, Inc.>
[&使用迅雷下载]
  <F:\工具\xunlei\geturl.htm, N/A>
[&使用迅雷下载全部链接]
  <F:\工具\xunlei\getallurl.htm, N/A>
[上传到QQ网络硬盘]
  <F:\工具\AddToNetDisk.htm, N/A>
[导出到 Microsoft Office Excel(&X)]
  <res://F:\工具\OFFICE~1\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ自定义面板]
  <F:\工具\AddPanel.htm, N/A>
[添加到QQ表情]
  <F:\工具\AddEmotion.htm, N/A>
[用QQ彩信发送该图片]
  <F:\工具\SendMMS.htm, N/A>

gototop
 

接上:
正在运行的进程
[PID: 140][\SystemRoot\System32\smss.exe]  <Microsoft Corporation><5.00.2195.6601>
[PID: 168][\??\C:\WINNT\system32\csrss.exe]  <Microsoft Corporation><5.00.2195.6601>
[PID: 164][\??\C:\WINNT\system32\winlogon.exe]  <Microsoft Corporation><5.00.2195.6714>
    [C:\Program Files\Common Files\minfoKey.DLL]  <N/A><N/A>
    [C:\WINNT\system32\UNISPIM.IME]  <北京清华紫光软件股份有限公司><3.0.0.3045>
    [C:\WINNT\system32\upengine.dll]  <北京清华紫光软件股份有限公司><3.0.0.3045>
[PID: 216][C:\WINNT\system32\services.exe]  <Microsoft Corporation><5.00.2195.6700>
    [C:\WINNT\system32\dmserver.dll]  <VERITAS Software Corp.><2195.6605.297.3>
[PID: 228][C:\WINNT\system32\lsass.exe]  <Microsoft Corporation><5.00.2195.6695>
[PID: 392][C:\WINNT\system32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 420][C:\Program Files\Rising\Rav\CCenter.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
[PID: 436][C:\Program Files\Rising\Rav\Ravmond.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 1, 22>
    [C:\Program Files\Rising\Rav\BWList.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 18>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RSAPPMGR.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\CfgDll.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\RsLog.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 20>
    [C:\Program Files\Rising\Rav\HOOKSYS.dll]  <Rising><18, 1, 0, 9>
    [C:\Program Files\Rising\Rav\Scanner.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 30>
    [C:\Program Files\Rising\Rav\libload.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\VirusLib.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\regmon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\HookWeb.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\MemMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\Program Files\Rising\Rav\expscan.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
    [C:\Program Files\Rising\Rav\mPorts.dll]  <Beijing Rising Technology Co., Ltd.><4, 0, 0, 3>
    [C:\Program Files\Rising\Rav\MailMon.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 5>
    [C:\Program Files\Rising\Rav\SpamEng.dll]  <N/A><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\engine.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 28>
    [C:\Program Files\Rising\Rav\PostTrt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 9>
    [C:\Program Files\Rising\Rav\UnExe.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\ScanExec.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 11>
    [C:\Program Files\Rising\Rav\ScanEx.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 10>
    [C:\Program Files\Rising\Rav\NvFile.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\Program Files\Rising\Rav\ScanMac.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 7>
    [C:\Program Files\Rising\Rav\ScanSct.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 15>
    [C:\Program Files\Rising\Rav\Unpacker.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\Program Files\Rising\Rav\ExtOLE.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 6>
    [C:\Program Files\Rising\Rav\RsStore.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 2>
    [C:\Program Files\Rising\Rav\ExtMail.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
[PID: 480][C:\WINNT\system32\spoolsv.exe]  <Microsoft Corporation><5.00.2195.7059>
[PID: 528][C:\WINNT\System32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 556][F:\KV2006\KVSrvXP.exe]  <Jiangmin Co. Ltd><9.2.0.50822>
    [F:\KV2006\UpdateX.dll]  <JiangMin Co.Ltd.><9, 0, 5, 913>
    [F:\KV2006\SvcSafe.dll]  <Jiangmin Co. Ltd><9, 2, 0, 51107>
    [F:\KV2006\lang\SvcSafe0804.lng]  <N/A><N/A>
    [F:\KV2006\RegProt.dll]  <Jiangmin Co.Ltd><9, 0, 5, 1212>
    [F:\KV2006\Scan.dll]  <Jiangmin Co., Ltd.><1.0.6.05190>
    [F:\KV2006\FileGD.dll]  <Jiangmin Co.Ltd><9.2.0.50809>
    [F:\KV2006\KvSPI.dll]  <Jiangmin Co. Ltd.><1.0.6.06030>
    [F:\KV2006\lang\KVSpi0804.lng]  <N/A><N/A>
    [F:\KV2006\ScanHost.dll]  <Jiangmin Co. Ltd><9, 2, 0, 50822>
    [F:\KV2006\KVWPSet.dll]  <Jiangmin Co.Ltd><9, 0, 0, 60220>
    [C:\Program Files\Common Files\minfoKey.DLL]  <N/A><N/A>
    [F:\KV2006\EngPS.dll]  <Jiangmin Co.Ltd><9, 2, 0, 50817>
    [F:\KV2006\KVEnhS.dll]  <Jiangmin Co., Ltd.><9, 2, 6, 02040>
    [F:\KV2006\KVEnhJ.dll]  <Jiangmin Co.Ltd><9, 1, 0, 50822>
    [F:\KV2006\KVExtCab.dll]  <JiangMin Co. Ltd><9, 2, 0, 50822>
    [F:\KV2006\KVExtEml.dll]  <Jiangmin Co. Ltd.><9, 2, 0, 51207>
    [F:\KV2006\lang\KVExtEml0804.lng]  <N/A><N/A>
    [F:\KV2006\KvExtZip.dll]  <JiangMin Co Ltd.><9, 2, 0, 50822>
    [F:\KV2006\KVExtZ.dll]  <Jiangmin Co. Ltd><9.2.0.503>
    [F:\KV2006\KVExtGz.dll]  <Jiangmin Co. Ltd><9, 0, 0, 51031>
    [F:\KV2006\KVExtTar.dll]  <Jiangmin Co. Ltd><9, 2, 0, 50822>
    [F:\KV2006\KVExtLZH.dll]  <JiangMin Co. Ltd.><9, 2, 6, 0316>
    [F:\KV2006\KvExtRar.dll]  <JiangMin Co. Ltd.><9, 2, 6, 04020>
    [F:\KV2006\KVEnhK.dll]  <Jiangmin Co.Ltd><9, 1, 0, 51209>
    [F:\KV2006\Fix.dll]  <Jiangmin Co.Ltd><9, 2, 0, 51011>
    [F:\KV2006\KvCkMail.dll]  <N/A><9, 0, 6, 605>
    [F:\KV2006\lang\KvMailRes0804.lng]  <N/A><N/A>
gototop
 

接上:
[C:\WINNT\system32\UNISPIM.IME]  <北京清华紫光软件股份有限公司><3.0.0.3045>
[PID: 600][C:\WINNT\system32\regsvc.exe]  <Microsoft Corporation><5.00.2195.6701>
[PID: 620][C:\WINNT\system32\MSTask.exe]  <Microsoft Corporation><4.71.2195.6920>
    [C:\Program Files\Common Files\minfoKey.DLL]  <N/A><N/A>
[PID: 660][C:\WINNT\system32\stisvc.exe]  <Microsoft Corporation><5.00.2195.6656>
[PID: 764][C:\Program Files\Rising\Rav\RavStub.exe]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 13>
    [C:\Program Files\Rising\Rav\RsCommX.dll]  <rising><18, 0, 0, 1>
    [C:\Program Files\Rising\Rav\RSCOMMON.DLL]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 4>
[PID: 864][C:\WINNT\System32\WBEM\WinMgmt.exe]  <Microsoft Corporation><1.50.1085.0100>
[PID: 876][C:\WINNT\system32\mspmspsv.exe]  <Microsoft Corporation><7.10.00.3059>
[PID: 908][C:\WINNT\system32\svchost.exe]  <Microsoft Corporation><5.00.2134.1>
[PID: 1080][C:\WINNT\Explorer.EXE]  <Microsoft Corporation><5.00.3700.6690>
    [C:\Program Files\Common Files\minfoKey.DLL]  <N/A><N/A>
    [C:\WINNT\system32\UNISPIM.IME]  <北京清华紫光软件股份有限公司><3.0.0.3045>
    [C:\WINNT\system32\upengine.dll]  <北京清华紫光软件股份有限公司><3.0.0.3045>
    [C:\WINNT\DOWNLO~1\BDPlugin.dll]  <><1, 0, 1, 1>
    [C:\Program Files\TENCENT\Adplus\Adplus1.dll]  <Tencent><4, 0, 9, 90>
    [C:\Program Files\TENCENT\Adplus\SSAddr.dll]  <Tencent><4, 0, 9, 90>
    [F:\KV2006\KVHookG.dll]  <Jiangmin Co.Ltd><9.0.0.1226>
    [C:\WINNT\system32\RavExt.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 19>
    [C:\Program Files\WinRAR\rarext.dll]  <N/A><N/A>
    [F:\工具\qdshm.dll]  <><1, 0, 101, 20>
    [C:\PROGRA~1\3721\ske\contmenu.dll]  <N/A><N/A>
    [F:\KV2006\KvShell.dll]  <Jiangmin Co.Ltd><9, 0, 5, 830>
    [F:\KV2006\UpdateX.dll]  <JiangMin Co.Ltd.><9, 0, 5, 913>
    [F:\KV2006\lang\Kvxp0804.lng]  <N/A><N/A>
    [F:\KV2006\APIImpl.dll]  <JiangMin Ltd.><9.0.0.500>
    [F:\KV2006\KVBHO.dll]  <Jiangmin Co.Ltd><9.0.6.0113>
    [F:\KV2006\KVAddrDb.dll]  <Jiangmin Co.Ltd><9, 0, 0, 1018>
    [C:\WINNT\DOWNLO~1\BDHelper.dll]  <><1, 0, 0, 6>
    [C:\Program Files\Rising\Rav\RavScrCh.dll]  <Beijing Rising Technology Co., Ltd.><18, 0, 0, 3>
    [C:\WINNT\system32\ALSNDMGR.CPL]  <Avance Logic, Inc.><1, 0, 0, 3>
    [C:\WINNT\system32\igfxcpl.cpl]  <Intel Corporation><3,0,0,1502>
    [C:\WINNT\system32\hccutils.DLL]  <Intel Corporation><3,0,0,1502>
    [C:\WINNT\system32\igfxres.dll]  <Intel Corporation><3,0,0,1502>
    [C:\WINNT\system32\igfxress.dll]  <Intel Corporation><3,0,0,1502>
[PID: 1104][C:\WINNT\system32\Rundll32.exe]  <Microsoft Corporation><5.00.2134.1>
    [C:\WINNT\DOWNLO~1\BDPlugin.dll]  <><1, 0, 1, 1>
    [C:\Program Files\Common Files\minfoKey.DLL]  <N/A><N/A>
    [C:\WINNT\system32\UNISPIM.IME]  <北京清华紫光软件股份有限公司><3.0.0.3045>
    [F:\KV2006\KVHookG.dll]  <Jiangmin Co.Ltd><9.0.0.1226>
gototop
 

没有那两个文件啊,哥哥,隐含文件也没有啊,我在安全模式下看的
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT